Item logo image for Lumina X-Frame Bypass Pro

Lumina X-Frame Bypass Pro

Item media 2 (screenshot) for Lumina X-Frame Bypass Pro
Item media 1 (screenshot) for Lumina X-Frame Bypass Pro
Item media 2 (screenshot) for Lumina X-Frame Bypass Pro
Item media 1 (screenshot) for Lumina X-Frame Bypass Pro
Item media 1 (screenshot) for Lumina X-Frame Bypass Pro
Item media 2 (screenshot) for Lumina X-Frame Bypass Pro

Overview

Smartly analyze and bypass X-Frame-Options and CSP headers to allow iframing of any website on-demand.

Lumina X-Frame Bypass Pro - The Ultimate Iframe Enabler Tired of seeing the "Refused to display in a frame" error? Lumina X-Frame Bypass Pro is a robust, developer-first extension designed to intelligently bypass both X-Frame-Options and Content-Security-Policy (CSP) response headers, allowing you to embed and test any website inside an <iframe>, <embed>, or <object> instantly. Designed specifically for web developers, testers, and UI/UX designers, this tool removes modern cross-origin iframe restrictions locally so you can seamlessly test split-screen layouts, integrate third-party widgets in a sandbox, or analyze responsive designs on your local machine. šŸš€ CORE FEATURES: Global Override Mode: A single switch to strip blocking headers across all tabs and URLs temporarily. Precision Domain Bypassing: Only want to test a specific integration? Target specific domains to keep your broader browsing session 100% secure. Manifest V3 Architecture: Built entirely on Chrome's latest declarativeNetRequest APIs. This guarantees lightning-fast network interception with zero performance throttling. Universal Unblock: Successfully handles strict X-Frame-Options: DENY / SAMEORIGIN and Content-Security-Policy: frame-ancestors rules. Zero Configuration: No complex regex or JSON rules to write. Just click the toggle icon and start embedding. šŸ›”ļø PRIVACY & SECURITY FIRST: This extension runs entirely 100% offline. No user data is collected, no analytics are tracked, and no telemetry is sent to third-party servers. Disclaimer: Disabling iframe protection removes essential anti-clickjacking security mechanisms. Please use this tool temporarily for development and testing purposes only.

Details

  • Version
    1.0.0
  • Updated
    April 13, 2026
  • Offered by
    Mochi Studio
  • Size
    482KiB
  • Languages
    English
  • Developer
    Email
    thangnd520@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization
The developer has disclosed that it will not collect or use your data. To learn more, see the developer’s privacy policy.

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes

Support

Related

Anti-CORS, anti-CSP

4.1

Enable cross origin requests blocked by CORS or CSP. Disable CORS and CSP in selected hostnames, preserve security of other websites

Header Lab – Request Headers & Redirects

5.0

Modify request headers and redirect URLs with regex rules, reusable profiles, conflict detection, and local-only storage.

CSP DSB

5.0

Modify or remove Content-Security-Policy headers on any website. Edit directives or use no-csp to disable CSP entirely.

Allow X-Frame-Options

5.0

Easily remove X-Frame-Options from the response header.

Iframe Buddy

0.0

Allow all iframes by dropping X-Frame-Options and Content-Security-Policy HTTP headers. Handy test button. Works with MV3 in 2024+!

Locator Lens

5.0

Extract XPath locators from any web page for any test automation framework

CORS Helper

1.0

Developer tool to bypass CORS restrictions during local testing. Features profiles, allowlist, and auto-off timer for safety.

DevHeader - Header Injector & HTTP Header Editor

5.0

Add & edit HTTP request and response headers per site. Fix CORS, set profiles, paste-to-add. No sign-up, no paywall.

RequestFlow Pro — HTTP Request Header & Query Param Overrider

0.0

Effortlessly override, add, or modify HTTP request headers, query parameters, and upstream responses using URL matching.

Ignore X-Frame headers

4.4

Drops X-Frame-Options and Content-Security-Policy HTTP response headers, allowing all pages to be iframed.

CORS Bypass — Per-Site CORS Unblock

3.0

Bypass CORS errors per-site with one click. Zero CPU overhead, smart domain protection. Built for developers.

Framer - Make IFrames possible!

5.0

Drop X-Frame-Options and Content-Security-Policy HTTP response headers for special sites, allowing pages to be embedded as iframes.

Anti-CORS, anti-CSP

4.1

Enable cross origin requests blocked by CORS or CSP. Disable CORS and CSP in selected hostnames, preserve security of other websites

Header Lab – Request Headers & Redirects

5.0

Modify request headers and redirect URLs with regex rules, reusable profiles, conflict detection, and local-only storage.

CSP DSB

5.0

Modify or remove Content-Security-Policy headers on any website. Edit directives or use no-csp to disable CSP entirely.

Allow X-Frame-Options

5.0

Easily remove X-Frame-Options from the response header.

Iframe Buddy

0.0

Allow all iframes by dropping X-Frame-Options and Content-Security-Policy HTTP headers. Handy test button. Works with MV3 in 2024+!

Locator Lens

5.0

Extract XPath locators from any web page for any test automation framework

CORS Helper

1.0

Developer tool to bypass CORS restrictions during local testing. Features profiles, allowlist, and auto-off timer for safety.

DevHeader - Header Injector & HTTP Header Editor

5.0

Add & edit HTTP request and response headers per site. Fix CORS, set profiles, paste-to-add. No sign-up, no paywall.

Google apps